Getting Data In

timestamp date in header, time in every event

evidales
Engager

Hi,
I have a log that the date part of the timestamp for every event only comes in the header and footer. I am able to parse the header, but that gives the same timestamp to every event.
Using a time_prefix: ([^,]+,){4} and the regex %H%M%S%2N to parse the last value as the time, it sometimes says that it is unable to parse it to a strptime and other times it parses it ok, even using the date of the header.

Log sample:

20181214,092255

9688,P088,I,01001,09441963

9688,P088,O,01001,09441984

9689,P088,I,01001,09442063

9689,P088,O,01001,09442077

9706,P015,I,05001,09442099

20181214,175510

Any help in ensuring a proper timestamp parsing in every occasion will be highly appreciated.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...